What the vendor says is affected
The collected bulletin did not provide a separate affected-products list. Check the original bulletin before making an exposure decision.
What the vendor recommends
We identified the following: - CVE-2026-5485: OS command injection in browser-based authentication component (Linux only, fixed in 2.0.5.1) - CVE-2026-35558: Improper neutralization of special elements in authentication components - CVE-2026-35559: Out-of-bounds write in query processing components - CVE-2026-35560: Improper certificate validation in identity provider connection components - CVE-2026-35561: Insufficient authentication security controls in browser-based authentication components - CVE-2026-35562: Allocation of resources without limits in parsing components Impacted versions: CVE-2026-5485 was addressed in 2.0.5.1 (Linux only).
Review the complete instructions on the vendor's siteWhat changed in later vendor updates
SecurityAlert records field-level changes from the point we begin following a bulletin. Earlier vendor changes may not have a field-by-field record.
- The vendor changed the advisory's last-updated date.
When this advisory changed
- Added to SecurityAlert
We collected the advisory from the official source.
- Published by AWS
The publication date reported by the vendor.
- Confirmed at the source
Our collector saw this advisory during a later source check.